{"id":251395,"date":"2023-09-27T10:43:59","date_gmt":"2023-09-27T14:43:59","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/en\/?p=251395"},"modified":"2025-07-01T18:07:54","modified_gmt":"2025-07-02T01:07:54","slug":"windows-11-users-dont-fall-into-the-fake-password-generator-scam","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/windows-11-users-dont-fall-into-the-fake-password-generator-scam\/","title":{"rendered":"Windows 11 users, don&#8217;t fall into the fake password generator scam"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Proofpoint&#8217;s cybersecurity sleuths just unearthed a sly new malware, putting on its best Bitwarden impression to pilfer precious data from unsuspecting users. Big kudos to Malwarebytes&#8217; Senior Director of Threat Intelligence, J\u00e9r\u00f4me Segura, for giving them the heads up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This digital menace, now labeled ZenRAT, is basically like that knockoff purse seller in a digital alleyway. Here&#8217;s the sneaky part: The culprits snagged the domain &#8220;bitwariden[.]com&#8221;, a crafty typo that&#8217;s eerily close to the real deal. In the tech world, we call this cheeky maneuver typosquatting. And they didn&#8217;t stop there. They meticulously crafted a website that&#8217;s the spitting image of Bitwarden&#8217;s. Tricky, right?<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Windows 11\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/3a83edc2-8bcb-4baa-8fbe-3ddcf458c1a4\/1709716978\/windows-11-win11icon.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Windows 11<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/windows-11.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/windows-11.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n<h2 class=\"wp-block-heading\">Windows 11 users, be careful<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So, how did these digital tricksters spread the word about their deceptive domain? Proofpoint&#8217;s brainiacs are betting on tactics like SEO poisoning, malvertising, or the old-fashioned charm of social engineering.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s the silver lining for Mac and Linux device fans: stroll onto the fake site and hit download, and you&#8217;ll be whisked away to a harmless page. But for <a href=\"https:\/\/en.softonic.com\/articles\/the-windows-11-snipping-tool-brings-exciting-improvements-on-the-way\" target=\"_blank\" rel=\"noreferrer noopener\" title=\"Windows 11\">Windows 11<\/a> users \u2013 it&#8217;s a trap! Click that link, and you&#8217;re rolling out the welcome mat for ZenRAT.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2023\/09\/windows-11_02-1024x683.jpg\" alt=\"\" class=\"wp-image-251397\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/09\/windows-11_02-1024x683.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/09\/windows-11_02-300x200.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/09\/windows-11_02-768x512.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/09\/windows-11_02-150x100.jpg 150w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/09\/windows-11_02.jpg 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Once ZenRAT&#8217;s made itself at home, it dials up its command &amp; control pals (or C2, if you&#8217;re in the know). This malware then goes on a data-hunting spree. Using crafty WMI queries, it&#8217;ll snoop around for your CPU name, GPU name, OS version (did we mention Windows 11 users should beware?), RAM stats, IP details, and even that antivirus software you&#8217;re running. And, oh boy, if you&#8217;ve stored credentials in your browser, ZenRAT&#8217;s snatching those too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Proofpoint&#8217;s sage advice? Stick to trusted digital watering holes when downloading software. Yet, here&#8217;s the kicker: even the keen-eyed can be duped. Picture this: a sham Bitwarden ad sneaking onto Google. Given the doppelganger website and the sneaky URL, this scheme can reel in quite the catch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As for the damage report? We&#8217;re still tallying up how many folks have been bamboozled into downloading this treacherous malware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Proofpoint&#8217;s cybersecurity sleuths just unearthed a sly new malware, putting on its best Bitwarden impression to pilfer precious data from unsuspecting users. Big kudos to Malwarebytes&#8217; Senior Director of Threat Intelligence, J\u00e9r\u00f4me Segura, for giving them the heads up. This digital menace, now labeled ZenRAT, is basically like that knockoff purse seller in a digital &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/windows-11-users-dont-fall-into-the-fake-password-generator-scam\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Windows 11 users, don&#8217;t fall into the fake password generator scam&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9290,"featured_media":251396,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[3149],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-251395","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionwindows-11"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/251395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9290"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=251395"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/251395\/revisions"}],"predecessor-version":[{"id":317643,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/251395\/revisions\/317643"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/251396"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=251395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=251395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=251395"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=251395"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=251395"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=251395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}